Skip to main content
Loyca

What the Kenya Data Protection Act requires of your business

· 5 min read

A plain-language walkthrough of controller and processor duties under Kenya's Data Protection Act 2019, ODPC registration, and the 72-hour breach clock.

The Data Protection Act 2019 (Act No. 24 of 2019) has been in force since November 2019, and the Office of the Data Protection Commissioner has been issuing determinations and penalty notices since 2022. If your organisation holds a customer list, a payroll file, or a CCTV recording, the Act applies to you. This is what it actually asks for.

Are you a controller or a processor?

The Act draws the same distinction as the GDPR, and it decides which duties land on you.

  • A data controller determines the purpose and means of processing. If you decided to collect the data and what to do with it, that is you.
  • A data processor processes personal data on behalf of a controller. Your payroll bureau, your cloud CRM vendor, and your outsourced call centre are processors.

Most organisations are both: a controller for their own staff and customers, a processor for whatever they handle on a client's behalf. The two roles carry different obligations and need separate answers, which is why the register described below needs a column for it.

The principles you are measured against

Section 25 sets out the data protection principles. In practice they translate to a short list of questions a supervisor can ask you, in order:

  1. Lawfulness, fairness and transparency. What is your lawful basis for this processing? Consent is one of several, and usually the weakest to rely on.
  2. Purpose limitation. Did you say what you would use it for, and are you using it only for that?
  3. Minimisation. Do you need every field you collect? The date-of-birth box nobody reads is a liability, not a feature.
  4. Accuracy. Can you correct a record, and does the correction propagate?
  5. Storage limitation. When does this get deleted? "Never" is not a retention policy.
  6. Integrity and confidentiality. The security obligation. This is where a technical assessment becomes evidence.
  7. Accountability. Can you show the above, on paper, without a week of preparation?
  8. Transfer restriction. Where does the data physically go, and on what basis does it leave Kenya?

The last one catches more Kenyan organisations than any other, because the answer is almost always "a cloud region outside Kenya" and almost never documented.

Registration with the ODPC

Data controllers and processors are required to register with the Commissioner. The Data Protection (Registration of Data Controllers and Data Processors) Regulations 2021 set the thresholds, and they exempt smaller entities by turnover and headcount — but the exemption does not apply to a list of activities, and that list captures most of the interesting cases: processing of sensitive personal data, health, financial services, telecommunications, direct marketing, and processing involving the transfer of data outside Kenya.

Two things worth knowing before you assume you are exempt:

  • The exemption is read against the activity, not just the size. A four-person fintech processing transaction data does not escape on headcount.
  • Registration is per legal entity, and it names a contact. If you have three subsidiaries, you have three conversations.

Check the current thresholds and the exempt-activity list on the ODPC's own site before deciding. The registration framework has been amended since the Act commenced, and a summary written a year ago is not a sound basis for a decision of this kind — including this one.

Data protection impact assessments

Section 31 requires a DPIA where processing is likely to result in high risk to the rights and freedoms of data subjects. The triggers that come up most often in this market:

  • Any new system processing health data
  • Credit scoring and alternative-data lending
  • Biometric enrolment, including fingerprint attendance systems
  • CCTV with facial recognition, or in a residential setting
  • Large-scale profiling for marketing

A DPIA is not a form. It is a short document that states the processing, the risks, the mitigations, and the residual risk somebody senior accepted. That last clause is the part that matters and the part most templates omit.

The 72-hour breach clock

Section 43 is the provision you will need at an inconvenient hour. Where a personal data breach occurs and there is a real risk of harm to the data subject, the controller must notify the Commissioner within 72 hours of becoming aware of it, and communicate to the affected data subject in writing.

Three details decide whether you meet it:

  • The clock starts at awareness, not at containment, and not when your investigation concludes. A helpdesk ticket describing a breach starts it, whether or not anyone senior has read the ticket yet.
  • Notification is required where there is a real risk of harm. That is an assessment you have to make and record — including when you decide the answer is no.
  • A processor who discovers a breach must tell the controller. If your contract does not say how fast, you have a gap that surfaces on the worst possible day.

Seventy-two hours is not long enough to decide who has authority to notify a regulator. That decision belongs in a document written now.

What enforcement looks like

The Commissioner can issue enforcement notices and penalty notices, and the Act caps administrative penalties by reference to a fixed maximum or a proportion of annual turnover — so for most organisations the financial exposure is real but bounded. The more expensive outcomes we see are the non-financial ones: an enforcement notice requiring you to stop a processing activity your revenue depends on, and the disclosure obligations that follow.

Where to start if you have done none of this

In order, because the order matters:

  1. Build the register. You cannot make a single defensible decision about data you have not inventoried. One row per processing activity: what data, whose, why, lawful basis, where it is stored, who it is shared with, how long you keep it, and whether you are controller or processor for it.
  2. Fix the lawful bases. The register will surface two or three activities running on consent that nobody actually collected.
  3. Write the breach playbook. Names, phone numbers, and the decision tree for the 72-hour question.
  4. Then do the notices, the DPIAs, and the registration.

Most organisations do this in reverse, starting with a privacy notice copied from a UK website. That produces a document describing a company that does not exist, which is exactly what a supervisor is trained to notice.

Primary sources

Read these rather than a summary, including this one:

Next step

If step 1 is where you are stuck, that is the piece of work we do most often, and it is scoped by the number of systems rather than the size of your company. See what a Data Protection & Privacy engagement covers, or bring the question to a 30-minute consultation — the register is usually the first hour of it.

Tagged

Share this

Written by

NEEDS_CONFIRMATION

Director, Loyca Limited

NEEDS_CONFIRMATION — 40–60 words, written in third person, naming actual credentials and years of experience. Do not draft this speculatively.

What we do about this

Practice areas

Message Loyca on WhatsApp